What the vulnerability does
01Description
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
Explanation of Vulnerability in Simple Terms
The Virtue/Ascend/Pinnacle Toolkit contains a cross-site scripting (XSS) vulnerability that allows an authenticated user to inject malicious scripts into the application. When another user views the affected page, the script executes in their browser, potentially compromising their session or stealing sensitive data. The vulnerability requires user interaction and affects the scope beyond the vulnerable component.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view affected pages.
Potential impact on your site
Authenticated users can compromise other users' sessions or steal data through injected scripts.
Conditions required to exploit
Attacker must be authenticated with low-level privileges and trick a user into visiting a crafted link or page.
Key dates
External resources
Related vulnerabilities